Skip to content

v2.153.0

Choose a tag to compare

@github-actions github-actions released this 29 May 23:33
04a9fd9

2.153.0 (2024-05-29)

Features

  • add actor_via_sso to audit log (#1002) (c52de4a)
  • add GOTRUE_<PROVIDER>_SKIP_NONCE_CHECK to skip nonce checks in ODIC flow (#1264) (4291959)
  • add is_sso_user column to users which allows duplicate emails to exist on those rows (#828) (0e2cd70)
  • add kid, iss, iat claims to the JWT (#1148) (3446197)
  • add provider claim to amr when the method is sso/saml (#837) (68acb95)
  • add array attribute mapping for SAML (#1526) (7326285)
  • add cleanup for session timebox and inactivity timeout (#1298) (9226979)
  • add cleanup of unverified factors in 24 hour window (#1379) (0100a80)
  • add configuration for custom sms sender hook (#1428) (1ea56b6)
  • add CORS allowed headers config (#1197) (7134000)
  • add custom access token hook (#1332) (312f871)
  • add custom sms hook (#1474) (0f6b29a)
  • add database cleanup logic, runs after each request (#875) (aaad5bd)
  • add different logout scopes (#1112) (df07540)
  • add email rate limit breach metric (#1208) (4ff1fe0)
  • add endpoint to resend email confirmation (#912) (a50b5a7)
  • add endpoint to unlink identity from user (#1315) (af83b34)
  • add error codes (#1377) (e4beea1)
  • add Figma provider (#1139) (007324c)
  • add fly oauth provider (#1261) (0fe4285)
  • add friendly name to enroll factor response (#1277) (3c72faf)
  • add generated admin client (#924) (3ee3f34)
  • add haveibeenpwned.org password strength check (#1324) (c3acfe7)
  • add idempotent refresh token algorithm (#1278) (b0426c6)
  • add idle db connection options (duration, count, healthcheck period) (#811) (e187280)
  • add inactivity-timeout to sessions (#1288) (6c8a96e)
  • add index on user_id of mfa_factors (#1247) (6ea135a)
  • add kakao OIDC (#1381) (b5566e7)
  • add log entries for pkce (#1068) (9c3ba87)
  • add manual linking APIs (#1317) (80172a1)
  • add mfa cleanup (#1105) (f5c9afb)
  • add mfa indexes (#746) (cb6a879)
  • add MFA support (disabled by default) (#736) (940f582)
  • add mfa verification postgres hook (#1314) (db344d5)
  • Add new Kakao Provider (#834) (bafb89b)
  • add new Linkedin OIDC due to deprecated scopes for new linkedin applications (#1248) (f40acfe)
  • add opentelemetry tracer and metrics (#679) (650fa3b)
  • add password hashing metrics (#769) (47adfef)
  • add PKCE (OAuth) (#891) (cf47ec2)
  • add pkce recovery (#1022) (1954560)
  • add pkce to email_change routes (#1082) (0f8548f)
  • add required characters password strength check (#1323) (3991bdb)
  • add safe deferred closing (#945) (29c431f)
  • add SAML config (disabled by default) (#759) (91fa9bd)
  • add saml metadata force update every 24 hours (#1020) (965feb9)
  • add send email Hook (#1512) (cf42e02)
  • add session id to required claim for output of custom access token hook (#1360) (31222d5)
  • add single session per user with tags support (#1297) (69feebc)
  • add soft delete option to admin delete endpoint (#489) (2a2f425)
  • add sso pkce (#1137) (2c0e0a1)
  • add support for Azure CIAM login (#1541) (1cb4f96)
  • add support for Twilio Verify (#1124) (7e240f8)
  • add test OTP support for mobile app reviews (#1166) (2fb0cf5)
  • add time-boxed sessions (#1286) (9a1f461)
  • add timeout middleware (#1529) (f96ff31)
  • add turnstile support (#1094) (b1d2f1c)
  • add weak password check on sign in (#1346) (8785527)
  • allow POST /verify to accept a token hash (#1165) (e9ab555)
  • allow whatsapp channels with Twilio Verify (#1207) (ff98d2f)
  • allow for postgres and http functions on each extensibility point (#1528) (348a1da)
  • allow more than one verified factor per user (#856) (47e4afc)
  • allow unverified email signins (#1301) (94293b7)
  • allow updating saml providers metadata_xml (#1096) (20e503e)
  • alter tag to use raw (#1427) (53cfe5d)
  • anonymous sign-ins (#1460) (130df16)
  • azure oidc fix (#1349) (97b3595)
  • calculate aal without transaction (#1437) (8dae661)
  • clean up expired factors (#1371) (5c94207)
  • clean up test setup in MFA tests (#1452) (7185af8)
  • complete OIDC support for Apple and Google providers (#1108) (aab7c34)
  • configurable NameID format for SAML provider (#1481) (ef405d8)
  • deprecate and explicitly allow freeform ID token issuers (#934) (99df661)
  • deprecate existing webhook implementation (#1417) (5301e48)
  • drop restriction that PKCE cannot be used with autoconfirm (#1176) (0a6f218)
  • drop SAML RelayState IP address check (#1376) (6284d99)
  • drop sha hash tag (#1422) (76853ce)
  • expose email address being sent to for email change flow (#1231) (f7308ad)
  • fix account linking (#1098) (93d12d9)
  • fix empty string parsing for GOTRUE_SMS_TEST_OTP_VALID_UNTIL (#1234) (25f2dcb)
  • fix refresh token reuse revocation (#1312) (6e313f8)
  • fix SAML metadata XML update on fetched metadata (#1135) (aba0e24)
  • forbid generating an access token without a session (#1504) (795e93d)
  • HTTP Hook - Add custom envconfig decoding for HTTP Hook Secrets (#1467) (5b24c4e)
  • ignore common Azure issuer for ID tokens (#1272) (4c50357)
  • infer Mail in SAML assertion and allow deleting SSO user (#1132) (47ad9de)
  • initial fix for invite followed by signup. (#1262) (76c8eeb)
  • internalize implementation (#925) (1a52eb6)
  • make dropping users_email_key backward compatible (#995) (aff2fe6)
  • make error message in factor creation more obvious (#1374) (74af993)
  • make phone data type alter backward compatible (#994) (551793e)
  • merge provider metadata on link account (#1552) (bd8b5c4)
  • modify email duplicate lookup to use identities (#826) (a31545f)
  • new timeout writer implementation (#1584) (72614a1)
  • no email password resets for users with no email identity (#793) (21c37ed)
  • pass transaction to invokeHook, fixing pool exhaustion (#1465) (b536d36)
  • password sign-up no longer blocks the db connection (#1319) (84d4b75)
  • PKCE magic link (#1016) (6fdad13)
  • prefix release with v (#1424) (9d398cd)
  • properly return hook error (#1355) (890663f)
  • refactor for central password strength check (#1321) (5524653)
  • refactor generate accesss token to take in request (#1531) (e4f2b59)
  • refactor hook error handling (#1329) (72fdb16)
  • refactor one-time tokens for performance (#1558) (d1cf8d9)
  • refactor password changes and logout (#1162) (b079c35)
  • refactor PKCE FlowState to reduce duplicate code (#1446) (b8d0337)
  • refactor resource owner password grant (#1443) (e63ad6f)
  • reinstate upgrade whatsapp support on Twilio Programmable Messaging to support Content API (#1266) (00ee75c)
  • remove id_token flow with freeform provider (#927) (2646967)
  • remove SafeRoundTripper and allow private-IP HTTP connections (#1152) (773e45e)
  • remove duplicate add_identities_email_column migrations, reorder others (#863) (ed08260)
  • remove flow state expiry on Magic Links (PKCE) (#1179) (caa9393)
  • remove legacy lookup in users for one_time_tokens (phase II) (#1569) (39ca026)
  • remove non-SSO restriction for MFA (#1378) (9ca6970)
  • remove opentracing (#1307) (93e5f82)
  • remove saml beta warning (#1003) (794dab0)
  • remove unused API NewAPIFromConfigFile (#909) (f91a450)
  • rename gotrue to auth (#1340) (8430113)
  • rename package to supabase from netlify (#947) (4f5c2f6)
  • require different passwords on update (#1163) (154dd91)
  • retry concurrent refresh token attempts (#1202) (d894012)
  • return expires_at in addition to expires_in (#1183) (3cd4bd5)
  • return bad request error when factor with duplicate friendly name is registered (#1375) (55febd2)
  • return SMS ID when possible (#1145) (02cb927)
  • revert "remove id_token flow with freeform provider" (#933) (4d98e30)
  • saml: add not_after column to sessions table (not used) (#810) (8d7477a)
  • saml: add SAML ACS handler (disabled by default) (#779) (ae83dce)
  • saml: add SAML metadata endpoint (disabled by default) (#775) (41668b7)
  • saml: add session expiration (not after timestamp) support (disabled by default) (#812) (6c6d3ad)
  • saml: add SSO authorization API (disabled by default) (#786) (fc6f58d)
  • saml: add SSO/SAML admin endpoints (disabled by default) (#771) (273b41f)
  • saml: add SSO/SAML migrations (#762) (437e683)
  • saml: add X.509 Distinguished Name to generated certificate (#801) (8d85788)
  • saml: remove unused features, small refactors (#846) (61c8eb8)
  • saml: return JSON response on POST /sso with optional JSON response (#800) (dfe9143)
  • send over user in SendSMS Hook instead of UserID (#1551) (d4d743c)
  • serialized access to session in refresh_token grant (#1190) (a8f1712)
  • set updated_at on refresh_tokens when revoking family (#1167) (bebd27a)
  • simplify token reuse algorithm (#1072) (9ee3ab6)
  • split validation and population of hook name (#1337) (c03ae09)
  • spotify oauth (#1296) (cc07b4a)
  • strip user-agent from otel tracing (#1309) (d76f439)
  • support for whatsapp as a channel for sending OTPs (#981) (d0d079f)
  • switch to github.com/supabase/mailme package (#1159) (dbb9cf7), closes #870
  • unlinking primary identity should update email (#1326) (bdc3300)
  • update github.com/lestrrat-go/jwx/jwk to 1.2.25 (#926) (ff8ee5a)
  • update chi version (#1581) (c64ae3d)
  • update github.com/coreos/go-oidc/v3@v3.6.0 (#1115) (23c8b45)
  • update github.com/rs/cors to v1.9.0 (#1198) (27d3a7f)
  • update oauth1.a flow (#1382) (4f39d2e)
  • update openapi spec with identity and is_anonymous fields (#1573) (86a79df)
  • update primary key for identities table (#1311) (d8ec801)
  • update publish.yml checkout repository so there is access to Dockerfile (#1419) (7cce351)
  • update README.md to trigger release (#1425) (91e0e24)
  • update to Go 1.19 (#770) (e6525ab)
  • upgrade whatsapp support on Twilio Programmable Messaging (#1249) (c58febe)
  • use DO blocks around SQL statements in migrations (#1335) (061391a)
  • use otherMails with Azure (#1130) (fba1988)
  • use template/text instead of strings.Replace for phone OTP messages (#1188) (5caacc1)
  • use account linking algorithm (#829) (c709ed5)
  • use dummy instance id to improve performance on refresh token queries (#1454) (656474e)
  • use OIDC ID token for Azure (#1269) (57e336e)
  • use unique message IDs for emails to prevent grouping (#986) (aaf2765)

Bug Fixes

  • #1218 fixes existing migrations to allow namespaces!="auth" (#1279) (206fc09)
  • createNewIdentity uses provided transaction (#776) (3f61950)
  • account linking logic (#990) (17162c9)
  • add email as verification type for email OTPs (#885) (8d21cbc)
  • add check for max password length (#1368) (41aac69)
  • add checks for ownership for unenroll and verify (#835) (bdd9947)
  • add cleanup statement for anonymous users (#1497) (cf2372a)
  • add db conn max idle time setting (#1555) (2caa7b4)
  • add discord global_name to custom_claims (#1171) (3b1a5b9)
  • add error handling for hook (#1339) (7ac7586)
  • add guard check in case factor, session, or user are missing (#1099) (b4a3fec)
  • add http support for https hooks on localhost (#1484) (5c04104)
  • add improved HTTP metrics (#768) (2f78644)
  • add index on (session_id, revoked) in refresh_tokens (#765) (5ba3aca)
  • add index on identities.user_id (#781) (6c2c734)
  • add mfa migrations (#722) (afdb223)
  • add migration to backfill email identities (#823) (b54d60a)
  • add missing index on user_id under sessions (#763) (3332072)
  • add profiler server (#1158) (58552d6)
  • add redirectTo to email templates (#1276) (40aed62)
  • add separate config for sms rate limits (#860) (1ff475c)
  • add swagger docs (#695) (8eefabb)
  • add test for all sms providers (#676) (de6cd79)
  • add validation and proper decoding on send email hook (#1520) (e19e762)
  • add validation to admin update user (#717) (497ce10)
  • admin delete factor should be allowed to delete unverified factors (#854) (4c2bac3)
  • admin user create & update (#929) (5526627)
  • allow all URL forms in redirects (#711) (4ece9e3)
  • allow any oauth providers to pass query params (#757) (ac2e7ae)
  • allow gotrue to work with multiple custom domains (#999) (91a82ed)
  • allow transactions to be committed while returning a custom error (#1310) (8565d26)
  • backfill email identities for invited users (#914) (f7286dd)
  • bypass captcha for certain routes (#693) (70a6070)
  • Change Dockerfile.dev target from netlify to Supabase (#973) (ee74d52)
  • change email update flow to return both ? messages and # messages (#1129) (77afd28)
  • check err before using user (#1154) (53e1b3a)
  • check for pkce prefix (#1291) (05c629b)
  • check freq on email change (#1090) (659ca66)
  • check linking domain prefix (#1336) (9194ffc)
  • cleanup panics due to bad inactivity timeout code (#1471) (548edf8)
  • confirm email on email change (#1084) (0624655)
  • convert string -> *string for AAL and AMR (#785) (d887d18)
  • correct pkce redirect generation (#1097) (bdf93b4)
  • create identity for invited user (#895) (8ddf54b)
  • deprecate hooks (#1421) (effef1b)
  • disable allow unverified email sign ins if autoconfirm enabled (#1313) (9b93ac1)
  • do call send sms hook when SMS autoconfirm is enabled (#1562) (bfe4d98)
  • docs: remove bracket on file name for broken link (#1493) (96f7a68)
  • don't encode query fragment (#1153) (e414cb3)
  • don't update user metadata on subsequent signups (#825) (9e97a32)
  • drop mfa flag (#831) (f0642c0)
  • duplicate identity error on update user (#1141) (39ca89c)
  • enforce code challenge validity across endpoints (#1026) (be7c082)
  • error should be an IsNotFoundError (#1432) (7f40047)
  • expose provider under amr in access token (#1456) (e9f38e7)
  • expose x-total-count and link (#991) (e6dac54)
  • fetch new IDP metadata if stale (#833) (be3766d)
  • fill last_sign_in_at with a non-null value on backfilled email identities (#850) (ef1a51f)
  • fix flow state expiry check (#1088) (6000e70)
  • format test otps (#1567) (434a59a)
  • garbled text in sms message when message contains unicode (#971) (55544e2)
  • generate signup link should not error (#1514) (4fc3881)
  • generateLink should create identity for invite & signup (#774) (0032b65)
  • handle error properly for redirects (#887) (30c55e8)
  • handle oauth email check separately (#1348) (757989c)
  • ignore exchangeCodeForSession when captcha is enabled (#1121) (4970bbc)
  • impose expiry on auth code instead of magic link (#1440) (35aeaf1)
  • improve default settings used (4745451)
  • improve logging structure (#1583) (c22fc15)
  • improve MFA QR Code resilience so as to support providers like 1Password (#1455) (6522780)
  • improve perf in account linking (#1394) (8eedb95)
  • include /organizations in expected issuer exemption (#1275) (47cbe6e)
  • include email claim in identityData (#796) (930f5af)
  • include symbols in generated password (#1364) (f81a748)
  • invalidate email, phone OTPs on password change (#1489) (960a4f9)
  • IsDuplicatedEmail should filter out identities for the currentUser (#1092) (dd2b688)
  • linkedin provider issue with missing avatar url (#847) (895fc2a)
  • linkedin_oidc provider error (#1534) (4f5e8e5)
  • load user after sign-up to pull data from triggers (#712) (e553477)
  • log clearer internal error messages for verify (#1292) (aafad5c)
  • log correct referer value (#1178) (a6950a0)
  • log final writer error instead of handling (#1564) (170bd66)
  • logout cookies not cleared (#830) (596dd70)
  • lowercase emails (#714) (d65ba60)
  • lowercase oauth emails for account linking (#1125) (df22915)
  • maintain query params order (#1161) (c925065)
  • make add_mfa_indexes re-runnable (#827) (00c21d8)
  • make flow_state migrations idempotent, add index (#1086) (7ca755a)
  • make migration idempotent (#1079) (2be90c7)
  • make migration idempotent (#923) (c792443)
  • move all EmailActionTypes to mailer package (#1510) (765db08)
  • move creation of flow state into function (#1470) (4392a08)
  • nil pointer dereference in stale SAML metadata check (#977) (bb21c93)
  • OIDC provider validation log message (#1380) (27e6b1f)
  • only apply rate limit if autoconfirm is false (#1184) (46932da)
  • only create or update the email / phone identity after it's been verified (#1403) (2d20729)
  • only create or update the email / phone identity after it's been verified (again) (#1409) (bc6a5b8)
  • pass through redirect query parameters (#1224) (577e320)
  • patch secure email change (double confirm) response format. (#1241) (064e8a1)
  • pkce bug with magiclink (#1074) (4b84129)
  • pkce issues (#1083) (eb50ba1)
  • populate password verification attempt hook (#1436) (f974bdb)
  • POST /verify should check pkce case (#1085) (7f42eaa)
  • potential panics on error (#1389) (5ad703b)
  • preserve backward compatibility with Twilio Existing API (#1260) (71fb156)
  • prevent user email side-channel leak on verify (#1472) (311cde8)
  • properly escape redirectTo URL for magic links (#750) (cc1d49d)
  • rate limiting not applied on phone OTP (#788) (6a129f3)
  • refactor email sending functions (#1495) (285c290)
  • refactor factor_test to centralize setup (#1473) (c86007e)
  • refactor mfa and aal update methods (#1503) (31a5854)
  • refactor mfa challenge and tests (#1469) (6c76f21)
  • refactor request params to use generics (#1464) (e1cdf5c)
  • releaserc (#680) (3f7f39e)
  • remove captcha on id_token grant (#1175) (910079c)
  • remove deprecated LogoutAllRefreshTokens (#1519) (35533ea)
  • remove duplicated index on refresh_tokens table (#1058) (1aa8447)
  • remove foreign key constraint on refresh_tokens.parent (af00058)
  • remove organizations from fly provider (#1267) (c79fc6e)
  • remove redundant queries to get session (#1204) (669ce97)
  • rename from CustomSMSProvider to SendSMS (#1513) (c0bc37b)
  • rename metadata to data (#764) (70e354d)
  • resend email change (#1151) (ddad10f)
  • resend email change & phone change issues (#1100) (184fa38)
  • Resend SMS when duplicate SMS sign ups are made (#1490) (73240a0)
  • resolve nil pointer dereference issue (#813) (4d78d5f)
  • respect last_sign_in_at on secure password update (#1164) (963df37)
  • restrict mfa enrollment to aal2 if verified factors are present (#1439) (7e10d45)
  • return 404 instead of 500 in maybeLoadUserOrSession (#783) (92ddade)
  • return correct sms otp error (#1351) (5b06680)
  • return error if session id does not exist (#1538) (91e9eca)
  • return error if user not found but identity exists (#1200) (1802ff3)
  • return signup confirmation if signup is incomplete for magiclink / otp (#889) (8137dd8)
  • return the latest flow state (#1076) (00c9a11)
  • return unauthorized error for invalid jwt (#744) (85cff37)
  • Revert "feat: no email password resets for users with no email identi& (#822) (1129482)
  • Revert "fix: remove organizations from fly provider" (#1287) (84e16ed)
  • revert patch for linkedin_oidc provider error (#1535) (58ef4af)
  • revert refactor resource owner password grant (#1466) (fa21244)
  • saml: access DB with context for SSO admin functions (#805) (ca9ad7a)
  • saml: always request persistent NameID in authn requests (#840) (3c2b56e)
  • saml: correct SSO domain, SAML attribute mapping update logic (#816) (9dbdd61)
  • saml: not specifying domains should not delete all domains (#851) (c1ad911)
  • saml: persist attribute mappings on provider create and update (#802) (af7c8ba)
  • saml: saml user accounts not being set as is_sso_user (#841) (e290983)
  • saml: use SessionNotOnOrAfter from the authn. statement instead of conditions (#838) (35acc4c)
  • sanitizeUser leaks user role (#1366) (8ce9d3f)
  • set emailChange to email (#920) (c23b6ce)
  • set the otp if it's not a test otp (#1223) (3afc8a9)
  • show proper error message on textlocal (#1338) (44e2466)
  • skip captcha on POST /verify (#795) (eef1bb7)
  • skip rate limit if header not present (#706) (8fb0c1e)
  • sms verify should update is_anonymous field (#1580) (e5f98cb)
  • support email verification type on token hash verification (#1177) (ffa5efa)
  • support message IDs for Twilio Whatsapp (#1203) (77e85c8)
  • switch to aws roles (#893) (76c8710)
  • take into account test otp for twilio verify (#1255) (18b4291)
  • test otp with twilio verify (#1259) (ab2aba6)
  • unenroll should remove totp amr claim (#758) (c7a62de)
  • unlink identity bugs (#1475) (73e8d87)
  • unmarshal is_private_email correctly (#1402) (47df151)
  • update .yml to mfa (#731) (e034ca0)
  • update dependencies (1/2) (#1304) (accccee)
  • update email, phone identities on change (#824) (390e34d)
  • update file name so migration to Drop IP Address is applied (#1447) (f29e89d)
  • update from oauth_pkce to pkce (#1017) (63bc007)
  • update github.com/crewjam/saml from 0.4.8 to 0.4.9 (#839) (7a10a05)
  • update gobuffalo to v5.3.4 (#814) (aa1ff23)
  • update linkedin issuer url (#1536) (10d6d8b)
  • update password should logout all other sessions (#806) (4b4ca39)
  • update phone if autoconfirm is enabled (#1431) (95db770)
  • update settings & route for SAML (#1009) (f405615)
  • update soft deletion (#894) (6581728)
  • update suggested Go version for contributors to 1.21 (#1331) (9feeec4)
  • upgrade pop version (#1069) (969691f)
  • use pattern for semver docker image tags (#1411) (14a3aeb)
  • use api_external_url domain as localname (#1575) (ed2b490)
  • use clear hCaptcha error messages (#789) (2906976)
  • use configured redirect URL for external providers (#1114) (42bb1e0)
  • use email change email in identity (#1429) (4d3b9b8)
  • use linkedin oidc endpoint (#1254) (6d5c8eb)
  • use proper index name in 20221215195500_modify_users_email_unique_index (9eda0ab)
  • use started transaction, not a new one (#1196) (0b5b656)

Reverts

  • "fix: only create or update the email / phone identity after i& (#1407) (ff86849)